{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-007.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-007",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-007",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-007",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-007.json",
    "title": "Re-assessment when a change goes beyond what was foreseen",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each change is classified in CI against the pre-determined changes in the provider's instructions for use; a change beyond them, a changed intended purpose, or a new population, jurisdiction, autonomy level or vendor version triggers a re-assessment, an amended deployment decision record and a role decision in the registry entry on whether the deployer has become the provider.",
    "failureModes": [
      "A retrain, a new data source or a threshold moved beyond the provider's pre-determined changes ships as routine, and the deployer takes on provider duties without knowing it.",
      "A general-purpose assistant is put to work on hiring or credit through a configuration change, with no re-classification.",
      "A system reaches a new population, jurisdiction or autonomy level with no re-assessment trigger record."
    ],
    "scope": "Changes to a deployed AI system, its intended purpose or its context of use, whether the deployer built the system or procured it.",
    "enforcementPoints": [
      "pre_merge",
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Change record classified against the pre-determined changes, and the amended deployment decision record with its role assessment",
        "schemaId": "deployment-decision-record",
        "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "require_approval",
      "text": "A change classified as beyond the pre-determined changes, or as a new purpose, goes back through classification and a new decision before it ships."
    },
    "layer": 2,
    "secondaryLayers": [
      1
    ],
    "patterns": [],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "instructions-for-use",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-instructions-for-use"
      },
      {
        "kind": "schema",
        "ref": "deployment-decision-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART25",
          "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 25,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"When a deployer becomes a provider\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#when-a-deployer-becomes-a-provider",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Maintenance calendar and retraining governance\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#maintenance-calendar-and-retraining-governance",
        "verified": "primary"
      },
      {
        "n": 26,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 25",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 25 (value chain: name or trademark, substantial modification or changed intended purpose makes a deployer the provider). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_25",
        "verified": "primary"
      },
      {
        "n": 10,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13 (instructions for use: capabilities and limitations of performance; pre-determined changes; human oversight measures; expected lifetime and maintenance; log collection). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_13",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Detect each trigger where it happens: a brand check in the release checklist for a name or trademark, change classification in CI for a substantial modification, and intake and the downstream use register for a changed purpose.",
      "Log the compute of every fine-tune of a general-purpose model as an artefact filed with the AIBOM: whether the modifier becomes a provider turns on an indicative criterion of one third of the original training compute."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "Whether a given change is a substantial modification is a legal call the source material leaves to counsel; who signs off the classification in CI awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
